AI description
CVE-2026-48142 is a vulnerability affecting NGINX Plus and NGINX Open Source, specifically within the `ngx_http_charset_module`. This flaw arises when a location block is configured with both `source_charset utf-8;` and an additional `charset` directive, such as `charset koi8-r;`. Under these specific conditions, remote and unauthenticated attackers can send specially crafted requests. These requests can exploit the vulnerability to cause a heap buffer over-read in the NGINX worker process, which may result in limited disclosure of memory or a process restart.
- Description
- NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- Source
- f5sirt@f5.com
- NVD status
- Analyzed
- Products
- dos, nginx_gateway_fabric, nginx_ingress_controller, nginx_instance_manager, nginx_open_source, nginx_plus, waf
CVSS 4.0
- Type
- Secondary
- Base score
- 6.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- MEDIUM
CVSS 3.1
- Type
- Secondary
- Base score
- 4.8
- Impact score
- 2.5
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
- Severity
- MEDIUM
- f5sirt@f5.com
- CWE-125
- Hype score
- Not currently trending
🚨 Nginx 1.31.2 yayınlandı. Öne çıkan yamalar: • HTTP/3 + QUIC tarafında use-after-free açığı (CVE-2026-42530) • HTTP/2/gRPC proxy senaryolarında heap overflow riski (CVE-2026-42055) • charset_map UTF-8 işleme kaynaklı memory overread (CVE-2026-48142) Mutl
@ridvanyagli
18 Jun 2026
151 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
1 Quote
#nginx 1.30.3 で CVE-2026-42055 と CVE-2026-48142 がfix か https://t.co/JC5hKJkY1X
@stuons
17 Jun 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
2026-06-17 nginx-1.30.3 stable and nginx-1.31.2 mainline versions have been released, (CVE-2026-42530),(CVE-2026-48142),(CVE-2026-42055), fix https://t.co/7HtZYwRWiH
@hacker_infra
17 Jun 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
nginx 1.30.3 and 1.31.2 released to fix CVE-2026-42055, CVE-2026-48142 and CVE-2026-42530 https://t.co/8dCg0h930B
@jedisct1
17 Jun 2026
681 Impressions
2 Retweets
10 Likes
0 Bookmarks
0 Replies
1 Quote
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:*",
"matchCriteriaId": "0772572C-26F9-4FA4-B9E6-BA40ED59F569",
"versionEndIncluding": "4.7.0",
"versionStartIncluding": "4.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:dos:4.9.0:*:*:*:*:nginx:*:*",
"matchCriteriaId": "DACAC9CB-16D3-4F55-A466-70035779B387",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*",
"matchCriteriaId": "15B7F1FD-0C49-460F-9CB8-23DA730EC4BE",
"versionEndIncluding": "1.6.2",
"versionStartIncluding": "1.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*",
"matchCriteriaId": "67499218-62EE-4217-897D-AF3E92D92E39",
"versionEndIncluding": "2.6.3",
"versionStartIncluding": "2.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "E54B5C35-49D7-43F6-B57C-4606F75192CE",
"versionEndIncluding": "3.7.2",
"versionStartIncluding": "3.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "DB6D172C-2716-40B9-B74C-D3029EDD171F",
"versionEndIncluding": "4.0.1",
"versionStartIncluding": "4.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "B4ED6BD2-BFBB-498C-9E43-508997695429",
"versionEndIncluding": "5.5.0",
"versionStartIncluding": "5.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "BCFCE3FC-61E0-4749-8F09-EEB4B09B1218",
"versionEndIncluding": "2.22.0",
"versionStartIncluding": "2.17.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
"matchCriteriaId": "AD753AAB-7ADA-4B0D-A33B-74E149277C4D",
"versionEndIncluding": "1.30.2",
"versionStartIncluding": "1.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
"matchCriteriaId": "4B3A862B-427A-440A-93AB-FFA1FB2E3909",
"versionEndIncluding": "1.31.1",
"versionStartIncluding": "1.31.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:*:*:*:*:long-term_support:*:*:*",
"matchCriteriaId": "7B91F29E-E9A7-4EB3-8858-2786A85E3005",
"versionEndExcluding": "37.0.2.1",
"versionStartIncluding": "37.0.0.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:*:*:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "277F91F7-F75B-463E-A342-4624E52ED3ED",
"versionEndExcluding": "r36",
"versionStartIncluding": "r33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r36:-:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "6FCF8770-25AF-4A07-916B-16F50357A44E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "D5C601A4-8DA6-443E-8284-6DCD34E4F3CB",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "EB6684A4-3869-4C21-B87A-129C30C99C28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "B2AC5070-A6B7-440B-A45A-90E751FF103E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "D7907F59-BBCC-4B5B-8BBC-92C14BB804D2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r36:p5:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "987F269A-A0F6-48D4-9C30-7F92A2267D45",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*",
"matchCriteriaId": "EB1118B4-3EA7-4A69-8259-86BB8837FC00",
"versionEndIncluding": "4.16.0",
"versionStartIncluding": "4.10.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*",
"matchCriteriaId": "2DB79E6C-08B0-4341-BCBE-B8070DDAA7AF",
"versionEndIncluding": "5.8.0",
"versionStartIncluding": "5.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*",
"matchCriteriaId": "03FC0AE0-1D26-4002-92DD-1895A38F6382",
"versionEndIncluding": "5.13.1",
"versionStartIncluding": "5.9.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]